4 ms·
could you share which technology are you using to encrypt all the traffic?
by cryptbe 13y ago
could you share which technology are you using to encrypt all the traffic?
- lsh123 13y ago* Mid-tier servers: standard HTTPS with nginx * Database: SSL connections for MySQL * Memcached, Gearmand, and other tools that don't have built-in SSL support: simple home grown message level encryption (AES256) And of course, there are VPN tunnels between data centers in addition to the above.
- cryptbe 13y agoThanks. > And of course, there are VPN tunnels between data centers in addition to the above. Could you please be more specific on the VPN solution that you are using? How do you manage the shared keys? How do you make sure 'system administrators can't easily read the traffic?"
- lsh123 13y agoWe use Cisco appliances for VPN (a few different models) and indeed there is a shared key that we have to input manually. However, after the key is entered (and configs saved) in order to decrypt the traffic one would need to print Cisco configs which is a very unusual operation that would be logged and then alerts will fire, audits will catch it, etc.
- josephlord 13y agoJust out of interest how do you transfer the key between datacentres for setup? Same person travels between them? PGP encrypted email? Or over the phone? Phone is I think an obvious (and now clearly wrong choice) although maybe always suspect if you are concerned with dark fibre . The endpoint security of a device generating and transmitting the key now also being a risk. How far up the chain do you worry? An airgapped device to generate the key and a single person travelling between datacentres seems the secure (although costly) solution. Obviously if TSA/customs remove device from them for inspection or connect it to anything it needs to be thrown away (or moved to insecure duties) and the setup process restarted.
- lsh123 13y agoI think public key encryption with long enough key is a pretty safe bet these days. Of course, NSA might have new non-public discoveries in math/crypto that might make public encryption obsolete. Or they might have a device form Area 51 that breaks any encryption. However, I haven't seen any evidences of this yet.
- stevenrace 13y ago>> in order to decrypt the traffic one would need to print Cisco configs Which could be done legally via 'Cisco Service Independent Intercept (SII)' built into IOS to comply with CALEA (Communications Assistance for Law Enforcement Act). And not so legally via user-escalation exploits within the same service. Anyway, props for making the effort. I too am interested in your key exchange methods.